← Vulnerability feed

Vulnerability record · CVE-2016-6143 · published 13 April 2017

CVE-2016-6143: Sap hana improper access control vulnerability

Sap · Hana

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

9.8 CVSS 3.0 Critical EPSS 3.6% · top 10.8% CWE-284 · Improper access control
9.8CVSS 3.0 base score, v2 7.5
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-6143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-7828Sap hana improper input validation vulnerabilitySAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified o…EPSS 6.5%9.8CVE-2021-21484Sap hana incorrect authorization vulnerabilityLDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…EPSS 1.2%9.8CVE-2016-6150Sap hana improper access control vulnerabilityThe multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac…EPSS 2.9%9.8CVE-2016-1928Sap hana memory buffer overflow vulnerabilityBuffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a craft…EPSS 6.2%9.3CVE-2016-1929Sap hana improper input validation vulnerabilityThe XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption an…EPSS 2.3%8.4CVE-2018-2402Sap hana information exposure vulnerabilityIn systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r…EPSS 1.5%8.1CVE-2016-6144Sap hana improper access control vulnerabilityThe SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_u…EPSS 3.8%7.5CVE-2018-2465Sap hana improper input validation vulnerabilitySAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauth…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2016-6143), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.